cGen is launching soon — reserve your spot for a demo

FDA Regulated Industries

Purpose-built for every
FDA-regulated sector

One validation platform, tuned to the regulations, terminology, and evidence each industry demands.

All companies regulated by the U.S. Food and Drug Administration — across food, drugs, OTC medicines, dietary supplements, medical devices, biologics, radiation-emitting electronic products, cosmetics, veterinary products, and tobacco products — must ensure that electronic records and electronic signatures used to meet applicable FDA recordkeeping or submission requirements comply with 21 CFR Part 11. Organisations conducting GMP-regulated activities for products manufactured, tested, released, or marketed in the European Union must also comply with EU GMP Annex 11 for computerised systems. Together, these requirements establish the controls necessary to ensure that regulated systems are validated, secure, traceable, and capable of maintaining complete, accurate, reliable, and readily available records throughout the system lifecycle. Compliance is essential for protecting patient safety, product quality, and data integrity — and for demonstrating during regulatory inspections that electronic records can be trusted as evidence of compliant operations.

Regulatory Foundation

FDA 21 CFR Part 11 & Computer Software Assurance (CSA)

21 CFR Part 11 (finalized in 1997) set the FDA’s expectations for using electronic records and electronic signatures in place of paper. FDA later issued the Part 11 “Scope and Application” guidance (2003) to clarify practical application and focus enforcement. CSA is FDA’s newer, risk-based approach for demonstrating confidence that software used in production and quality systems is fit for its intended use.

What Part 11 requires

  • Apply Part 11 controls when electronic records or signatures satisfy FDA recordkeeping or submission requirements (“predicate rules”).
  • Validate systems for intended use and protect data integrity — accuracy, completeness, security, and retention / retrieval.
  • Implement technical and procedural controls: role-based access, secure audit trails, and operational / authority checks.
  • Ensure e-signatures are uniquely attributable to an individual and managed to prevent repudiation or misuse.

What CSA is (and how it helps)

CSA recommends scaling assurance activities to the risk that software failure could impact product quality, patient / user safety, and data integrity. It encourages “right-sized” evidence — supplier evidence, automated testing, and targeted scripted testing for higher-risk functionality — while reducing low-value documentation.

Why companies must comply

  • Ensure electronic records and e-signatures are trustworthy for FDA inspections, quality decisions, and regulatory submissions.
  • Demonstrate control of computerized systems that create or maintain required GxP / quality records across the system lifecycle.
  • Manage risk efficiently — Part 11 sets baseline record and e-signature expectations; CSA aligns assurance effort to risk.
The Enforcement Record

What FDA actually finds
during inspections

These aren’t hypothetical risks. They’re observations from publicly available FDA inspection records — issued to regulated manufacturers who thought their systems were adequate.

Audit Trail

Trail not enabled

Instrument audit trail feature was not enabled — creation, modification, and deletion of records passed untracked.

Data Integrity

Unlocked master records

Master batch records stored as unlocked Excel files, open to alteration, duplication, and deletion by any user.

Part 11 / Annex 11

Systems non-compliant

GMP-related computerised systems across manufacturing workshops found not 21 CFR Part 11 / Annex 11 compliant.

Records Access

Documents disposed mid-inspection

Records not made readily available for authorised inspection — documents observed being discarded during the inspection.

Illustrative — drawn verbatim or paraphrased from publicly available FDA Form 483 and Warning Letter records (FDA.gov).

Form FDA 483 — Inspectional Observations

Real observations. Real language.

Form FDA 483s are issued at the close of an inspection when investigators observe conditions that may constitute violations. The excerpts below are reproduced verbatim from publicly available records.

FORM FDA 483Observation 6

Finished Drug Manufacturer · China · January 2024

"Your firm's GMP related computerized systems and equipment spread across manufacturing workshops are not 21 CFR part 11 compliant. [Equipment] have no time stamped audit trail, data management, alarm management, and archival and retrieval of records capabilities."

cGen IS DESIGNED TO ADDRESS THIS

  • Automatic, tamper-evident audit trails on every record action — enabled by default
  • Built-in Part 11 / Annex 11 controls: role-based access, electronic records, e-signatures, data retention
  • Inspection-ready audit trail export generated in seconds
FORM FDA 483Observation 6 — 16 pages, 13 observations

Finished Drug Manufacturer · India · March 2018

"Electronic records are used, but they do not meet requirements to ensure that they are trustworthy, reliable and generally equivalent to paper records… failed to assure the accuracy and reliability for data recorded which are derived or entered using non-validated and unprotected excel spreadsheet… QC department deleted 2,101 files since 1 March 2018."

cGen IS DESIGNED TO ADDRESS THIS

  • Controlled electronic records — no unmanaged spreadsheets in the validation lifecycle
  • Immutable audit trails prevent unauthorised deletion of any record
  • Validated, password-protected systems with role-based access by default

Illustrative — based on publicly available FDA enforcement records (FDA.gov). Records are publicly available via the FDA website.

Escalation Path

What happens after a 483

An inadequate response to a Form 483 does not end the matter. FDA escalates.

01

Form FDA 483

Observations issued at close of inspection

02

Inadequate Response

Corrective actions deemed insufficient

03

Warning Letter

Formal action — public record, CEO-addressed

04

Import Alert

Products refused US entry; firm flagged publicly

Warning LetterData Integrity / Part 11 / Annex 11

Finished Drug Manufacturer · South Korea · February 2020

MARCS-CMS 593158

"You stored your master batch records as unlocked Excel files which were open to alteration, duplication, and deletion by unauthorized personnel… your quality system does not adequately ensure the accuracy and integrity of data… Include a detailed description of the scope and root causes of your data integrity lapses."

Outcome: Import Alert 66-40

Warning LetterRecords & Documentation

Dietary Supplement Manufacturer · Hawaii, USA · April 2020

MARCS-CMS 599389

Significant violations of 21 CFR Part 111 (CGMP for Dietary Supplements): failed to establish identity specifications for components, no finished product specifications, no written master manufacturing records, no batch production records, no written complaint procedures, and no reserve samples maintained.

Outcome: Products adulterated & misbranded

Warning LetterQuality System / Data Integrity

Sterile Drug Manufacturer · Texas, USA · April 2026

MARCS-CMS 722729

"You lacked evidence that the follow-up project was actually initiated… your quality unit failed in its oversight of numerous investigations associated with repeated and systemic product quality deficiencies… Procedural updates and training alone do not address the systemic failures that allowed deficient investigations to persist undetected."

Outcome: Products adulterated — 2,500+ complaints, product recall

Warning LetterAI-Generated Specs / cGMP

Cosmetics & Drug Manufacturer · USA · April 2026

MARCS-CMS 722591

"Outsourcing document creation or compliance tracking to an AI model does not relieve human management and the Quality Unit of their legal responsibility to ensure absolute accuracy, validation, and adherence to federal drug regulations… your firm relied on AI-generated drug specifications without qualified human review or approval."

Outcome: Products adulterated — AI-generated specs unapproved

Warning LetterAI QA Automation / No Human Oversight

Medical Device Manufacturer · South Korea · May 2026

MARCS-CMS 725759

"Your firm used an AI tool to perform QA checks on drug manufacturing processes without a qualified QA representative conducting the review… traditional cGMP quality control mandates apply directly to AI tools just as they apply to legacy software or manual processes… AI-generated outputs cannot be auto-approved."

Outcome: cGMP violations — AI replaced human QA oversight

Warning LetterAI-Generated Documentation / Quality System

Health Technology · USA · August 2025

MARCS-CMS 707021

"AI-generated outputs, documentation, and data summaries cannot be auto-approved — they require rigorous human-in-the-loop accountability by qualified personnel… your firm's quality unit failed to review or verify AI-generated compliance records before releasing them as official quality system documentation."

Outcome: Quality system deficiencies — unreviewed AI documentation

cGen IS DESIGNED TO ADDRESS THIS

ALCOA++ data integrity: every record attributable, legible, contemporaneous, original, and accurate
Immutable, tamper-evident audit trails — evidence of every action, always available
Controlled electronic records — no unmanaged spreadsheets or unlocked files
Complete quality system documentation — master records, batch records, specifications
Built-in complaint management and CAPA workflows with automated tracking
Continuous monitoring and trend analysis flags systemic issues before FDA does
Human-in-the-loop by design — cGen AI Assistant drafts deliverables, but a qualified QA representative must review and approve every CSV/CSA record
AI outputs are clearly marked as drafts until a physical QA person signs off with Part 11-compliant electronic signatures
Full audit trail of every AI-generated artifact — who created it, who reviewed it, and what changed before approval

Illustrative — based on publicly available FDA enforcement records. Source documents publicly available via FDA.gov.

The Common Thread

Different companies.
Same root cause.

Every warning letter above — regardless of industry, geography, or product type — traces back to the same fundamental failure: no trustworthy electronic quality system to enforce records integrity, provide audit trail evidence, and give quality units real-time visibility. The newest letters make the point even sharper: AI does not replace your Quality Unit. Firms that let AI tools auto-generate specifications, run QA checks, or produce compliance documentation without qualified human review drew the same FDA response — your legal responsibility cannot be outsourced to a model.

01

Records without controls

Chemland — South Korea

Master batch records stored as unlocked Excel files. No access controls, no audit trail, no Part 11 / Annex 11 compliance. Anyone could alter, duplicate, or delete records without detection.

What Part 11 / Annex 11 was designed to prevent

02

Records that never existed

Hawaii Pharm — Hawaii, USA

No master manufacturing records, no batch production records, no complaint procedures, no reserve samples. The entire documentation infrastructure required by CGMP was absent.

What an electronic quality system enforces

03

Records that couldn’t be trusted

CareFusion / BD — Texas, USA

Cleaning logs said areas were clean — FDA found contamination everywhere. Follow-up projects had no evidence of initiation. Quality unit had no visibility into 2,500+ complaints. The records existed, but they didn’t reflect reality.

What continuous monitoring and audit trails solve

04

AI that replaced human judgement

Purolea Cosmetics Lab — USA

AI generated drug specifications and compliance documents that went straight to production — no qualified QA representative ever reviewed or approved them. FDA made clear: outsourcing to AI does not relieve the Quality Unit of its legal responsibility.

What human-in-the-loop enforcement prevents

05

AI that ran QA checks alone

BMC Medical Co., Ltd. — South Korea

An AI tool performed QA checks on drug manufacturing processes without a qualified person conducting the review. FDA confirmed that cGMP quality control mandates apply to AI tools exactly as they apply to legacy software or manual processes.

What mandatory QA sign-off enforces

06

AI docs without accountability

SeniorLife Technologies — USA

AI-generated documentation and data summaries were released as official quality system records without any human review. No one verified accuracy, completeness, or regulatory alignment before the documents entered the quality system.

What draft-to-approved workflows solve

cGen is built to make these failures structurally impossible — not by adding more paperwork, but by replacing it with controlled electronic records, immutable audit trails, and continuous quality monitoring that give your quality unit the evidence and visibility to act before FDA arrives. And when AI enters the picture, cGen keeps a qualified human in the loop — the cGen AI Assistant drafts your CSV/CSA deliverables, but every output stays in draft until a physical QA representative reviews and approves it with a Part 11-compliant electronic signature.

Part 11 / Annex 11

Electronic records & e-signatures active from day one

ALCOA++

Every record attributable, legible, and tamper-evident

Real-time

Quality unit dashboards with automated trend alerts

Always on

Continuous monitoring — not a point-in-time validation

Data Integrity Framework

The evolution to ALCOA++

From foundational data integrity principles to a comprehensive framework that ensures every record is trustworthy, complete, and inspection-ready.

A

ALCOA

THE FOUNDATION

A

Attributable

Who performed the action and when

L

Legible

Readable, permanent, and preserved

C

Contemporaneous

Recorded at the time of the activity

O

Original

Source data or a certified true copy

A

Accurate

Free from errors, complete, and truthful

+

ALCOA+

EXTENDED

All ALCOA principles, plus:

C

Complete

All data including repeat or reanalysis

C

Consistent

Dated, time-stamped in expected sequence

E

Enduring

Recorded on approved, durable media

A

Available

Accessible for review throughout retention

++

ALCOA++

NEXT GENERATION

All ALCOA+ principles, plus:

I

Integrity

Data is unaltered and tamper-evident

R

Robustness

Systems withstand failure and recover

T

Transparency

Processes are visible and auditable

A

Accountability

Clear ownership of data and actions

R

Reliability

Consistent, dependable, and reproducible

cGen enforces all ALCOA++ principles by design — every record, every audit trail, every signature.

See how cGen makes these failures structurally impossible

Controlled electronic records, immutable audit trails, and continuous monitoring — in one platform your quality unit and inspectors can trust.

FDA's Answer — February 2026

Computer Software Assurance
is now final guidance

FDA finalised its Computer Software Assurance (CSA) guidance on 3 February 2026. It redefines what good looks like — and leaves paper-first CSV approaches misaligned with agency expectations.

FDA CSA Guidance · February 2026

"FDA believes that applying a risk-based approach to computer software used as part of production or the quality management system would better focus manufacturers' quality assurance activities to help ensure product quality while helping to fulfill validation requirements."

This guidance represents FDA's current thinking and does not establish legally enforceable responsibilities.

Old CSV approach

CSA guidance now recommends

Exhaustive documentation at every stage regardless of risk
Evidence scaled to risk — rigour focused where failure matters most
Screenshot-heavy, paper-based test evidence packages
Objective electronic evidence: tool logs, automated results, supplier documentation
Validation as a one-time project with a sign-off date
Ongoing assurance across the software lifecycle — not a point-in-time event
Same effort applied uniformly across all systems
Risk-based triage: unscripted testing for lower-risk functions; scripted for higher-risk

HOW cGen IS DESIGNED TO ALIGN

Risk engine auto-classifies systems — right-sizing test effort without manual triage
Electronic evidence captured natively — no manual screenshot assembly
Continuous monitoring keeps assurance live post-go-live
Part 11 / Annex 11 electronic records & e-signatures active on day one

Who Must Comply

The FDA-regulated industries we serve

01

Food

Bottled water, food additives, infant formula, and food manufacturing — FSMA, HACCP, and FDA food-safety cGMP.

02

Drugs

Prescription drugs and generic medications — 21 CFR Parts 210/211 cGMP.

03

OTC Medicines

Over-the-counter drug manufacturing under 21 CFR Part 211 and the OTC monograph system.

04

Dietary Supplements

21 CFR Part 111 cGMP — identity, purity, strength, and composition of vitamins, minerals, and botanicals.

05

Medical Devices

From simple bandages to complex heart pacemakers — 21 CFR Part 820 QMSR, ISO 13485, and EU MDR / IVDR.

06

Biologics

Vaccines, blood products, gene therapies, and tissues — 21 CFR Parts 600–680 and cell & gene therapy traceability.

07

Radiation-Emitting Electronic Products

Microwaves, X-ray equipment, lasers, and televisions — 21 CFR Parts 1000–1050 performance standards.

08

Cosmetics

Skin care, makeup, perfumes, shampoos, and hair dyes — MoCRA facility registration and safety substantiation.

09

Veterinary Products

Livestock feed, pet food, and animal drugs — 21 CFR Parts 500–599 and CVM requirements.

10

Tobacco Products

Cigarettes, e-cigarettes, cigars, and smokeless tobacco — Center for Tobacco Products and PMTA-supporting validation.

Regulatory frameworks supported, out of the box

21 CFR Part 11

EU GMP Annex 11

GAMP 5 (2nd Ed)

ICH Q9(R1) / Q10

21 CFR Part 820

EU MDR / IVDR

FDA's FINAL Guidance on CSA (Published FEB 2026)

ISO 13485

PIC/S PI 011-3

WHO Annex 4

ICH M7

ALCOA++

cGen

cGen — AI-native computer system validation software for life sciences. Design, validate, and continuously monitor your GxP-regulated systems in one inspection-ready environment.

contact@compligen.ai(833) 916-CGEN(833-916-2436)

Merchandise Mart Plaza, Suite 470, Chicago, IL 60654

Compligen - cGen AI-native GxP suite by compligen | Product Hunt

Product

Resources

Company

© 2026 compligen.AI. All rights reserved.

21 CFR Part 11 GAMP 5 SOC 2 Type II EU GMP Annex 11

We value your privacy

We use analytics cookies to understand how you use our site. No advertising or tracking cookies.